We currently run v6.4.10 for our FMG-VM and manage bigger customer's FortiGates(FGTs) totalling about 600 (soon to be 800+).
And one of them needs one VIP group (two VIPs) at all 500+ locations. We use policy packages for this customer to standardize their policies, which is almost the same at all locations.
But when I looked at the VIP object config under Policy&Objects->Object Configurations->Firewall Objects->Virtual IPs then hit "Create New->Virtual IP", I don't see a way to select a dynamic address object for the External IP and Mapped IP.
This means we need to create 500+ x 2 VIPs manually putting each IP, then worse, we need to create 500+ different policies and use "Installation Target" to be for one specific FGT.
Is there a better way to have just one policy for one VIP group for 500+ FGTs?
Or, can I use meta fields+CLI template to define those on Device DB side and somehow let the policy to refer to the VIP group name?
There should be a better way to do this, right?